Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 67125 - net-dialup/ppp-2.4.2-r5 DEPENDs on insecure libpcap
Summary: net-dialup/ppp-2.4.2-r5 DEPENDs on insecure libpcap
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: GLSA Errors (show other bugs)
Hardware: All All
: High normal (vote)
Assignee: Gentoo Dialup Developers
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2004-10-11 10:34 UTC by Jeremy Huddleston (RETIRED)
Modified: 2004-10-14 01:07 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jeremy Huddleston (RETIRED) gentoo-dev 2004-10-11 10:34:00 UTC
net-dialup/ppp-2.4.2-r5 has a dependency on <=net-libs/libpcap-0.7.2-r1 which is vulnerable to the problem outlined in GLSA 200404-03.

ppp should be patched to work with the newer version of libpcap
Comment 1 solar (RETIRED) gentoo-dev 2004-10-11 12:41:32 UTC
Jeremy,
I'm reassigning this to net-dialup to fix/port. Add security@ if
to the CC: if you think it needs to be added otherwise letting the
maintainer of the package should handle this.
Comment 2 solar (RETIRED) gentoo-dev 2004-10-11 12:42:38 UTC
Adding myself to the CC: so I can watch the follow up to this bug.
Comment 3 Daniel Black (RETIRED) gentoo-dev 2004-10-12 04:13:16 UTC
net-libs/libpcap-0.7.2-r1 provides /usr/include/net/bpf.h which the newer versions don't have.

Copying the /usr/include/net/bpf.h from the old version of libpcap made ppp-2.4.2-r5 compile.

Netmon people - can this be fixed in libpcap?

Note that: qpkg -f -v /usr/include/nessus/net/bpf.h
net-analyzer/nessus-libraries-2.0.12 *

The libpcap version of the header file contains C++ support, BSD support and a lot of other definations.

I don't have much time to work on this. Assignments due on 14th. Feel free to change ppp to work as per my devaway message.
Comment 4 Alin Năstac (RETIRED) gentoo-dev 2004-10-13 10:02:16 UTC
why not putting 
 sed -e "s:net/bpf.h:pcap-bpf.h:"
in ppp's ebuild?
Comment 5 Alin Năstac (RETIRED) gentoo-dev 2004-10-13 11:59:00 UTC
correction: sed -e 's:net/bpf\.h:pcap-bpf.h:'
Comment 6 Daniel Black (RETIRED) gentoo-dev 2004-10-14 01:07:57 UTC
Netmons - ignore request - problem solved.

Alin thanks for the fix.

Solved in 2.4.2-r5